CVE-2013-7225
02.01.2014, 14:59
Multiple SQL injection vulnerabilities in app/controllers/home_controller.rb in Fat Free CRM before 0.12.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the homepage timeline feature or (2) the activity feature.
Vendor | Product | Version |
---|---|---|
fatfreecrm | fat_free_crm | 𝑥 ≤ 0.12.0 |
fatfreecrm | fat_free_crm | 0.9.6 |
fatfreecrm | fat_free_crm | 0.9.7 |
fatfreecrm | fat_free_crm | 0.9.8 |
fatfreecrm | fat_free_crm | 0.9.9 |
fatfreecrm | fat_free_crm | 0.9.10 |
fatfreecrm | fat_free_crm | 0.10.1 |
fatfreecrm | fat_free_crm | 0.11.0 |
fatfreecrm | fat_free_crm | 0.11.1 |
fatfreecrm | fat_free_crm | 0.11.2 |
𝑥
= Vulnerable software versions
References